# Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys

> Device code phishing abuses the OAuth 2.0 Device Authorization Grant (RFC 8628) to steal post-authentication access and refresh tokens, defeating every MFA form including FIDO2 passkeys because it targets the authorization layer rather than login. The technique moved from a 2020 research curiosity to nation-state tradecraft (Storm-2372, since August 2024) to a fully industrialized criminal commodity in 2025-2026 via phishing-as-a-service kits (EvilTokens, ARToken, Tycoon2FA, Kali365, and 25+ others tracked by Push Security), with Microsoft observing 10-15 new campaigns every 24 hours and Barracuda logging 7 million attacks in four weeks (April 2026).

- **Published:** 2026-07-31T00:00:00Z
- **Last reviewed:** 2026-07-31T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1793
- **ID:** TL-2026-1793
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Storm-2372 (Russia)
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Device code phishing exploits the OAuth 2.0 Device Authorization Grant, a flow designed for input-constrained devices (smart TVs, CLIs, IoT) where a user visits a verification URL on a separate, trusted device and enters a short code to authorize a session. Because the flow is entirely spec-compliant and occurs on the identity provider's own legitimate domain, it structurally bypasses every authentication-layer defense: passwords, OTPs, push MFA, and even phishing-resistant FIDO2/passkey authentication, since "proving your identity and granting access to an application are two different things" and this attack targets only the latter.

The canonical attack chain: an attacker requests a real device code from the identity provider (Microsoft, Salesforce, GitHub, AWS, etc.), then delivers a lure — a fake Teams meeting invite, an IT-helpdesk vishing call, a Telegram-distributed phishing kit lure, or a spoofed verification/CAPTCHA page — that instructs the victim to visit the provider's own legitimate device-login page and enter the attacker-supplied code. The victim authenticates normally and clicks "approve," and the identity provider issues an OAuth access token and refresh token directly to the attacker's polling client. No credentials or MFA codes are ever exposed to the attacker, and no authentication-layer control (conditional access risk scoring aimed at sign-in behavior, MFA fatigue, phishing-resistant hardware keys) fires, because the victim did, in fact, authenticate themselves.

The technique was first described by researchers in 2020 but remained a curiosity until Microsoft's Threat Intelligence Center identified Storm-2372, a threat actor assessed with medium confidence to align with Russian state interests, running an active device code phishing campaign since August 2024 against government, NGO, IT services, defense, telecom, healthcare, higher education, and energy/oil-and-gas targets across Europe, North America, Africa, and the Middle East. Storm-2372 impersonated prominent individuals over WhatsApp, Signal, and Teams to build rapport before sending fake meeting invitations; in February 2025 Microsoft observed the group evolve to abuse the Microsoft Authentication Broker client ID specifically to mint Primary Refresh Tokens (PRTs) and register attacker-controlled devices, extending persistence beyond simple token theft into full device-bound identity compromise that survives password resets.

In 2025-2026 the technique was industrialized as a criminal commodity. ShinyHunters (operating within the Scattered LAPSUS$ Hunters alliance alongside Scattered Spider and LAPSUS$, tracked separately as UNC6040 for the vishing cluster) combined voice phishing — cold-calling victims as fake IT support citing a "mandatory passkey rollout" or compliance issue — with device code phishing against Salesforce's /setup/connect flow, registering attacker-controlled "DataLoader" connected apps that impersonate Salesforce's legitimate Data Loader integration and request broad, refresh-token-capable API scopes. This campaign compromised over 1,000 organizations and produced roughly 1.5 billion stolen records, and was a contributing vector (via a September 2025 Salesforce tenant compromise) to the May 2026 Instructure/Canvas breach affecting approximately 275 million individuals across ~330 school Free-For-Teacher portals. Push Security separately tracked a 37.5x increase in device code phishing activity since the start of 2026 across 12+ distinct kits.

Commercial phishing-as-a-service platforms accelerated adoption further: Sekoia first documented EvilTokens in March 2026 ($1,500 one-time plus $500/month), after which Microsoft VP Tanmay Ganacharya reported 10-15 distinct new campaigns launching every 24 hours. Cisco Talos subsequently exposed ARToken, a React SPA operator panel sharing EvilTokens' API contracts and PRT lifecycle, exposing 80+ API endpoints for device code phishing, PRT persistence (setup/refresh/renew/reacquire/cookie), full Outlook mailbox and SharePoint/OneDrive access, and an automated BEC module ("ARTSender") that sends as the victim, creates evidence-suppressing inbox rules, and monitors compromised mailboxes for keywords in real time — Talos characterized it as "a complete BEC operations environment." ARToken layers a seven-stage client-side anti-bot/anti-analysis system (headless-browser and navigator.webdriver detection, mouse-trajectory validation, 800ms interaction gating) atop a server-side X-Antibot-Token (SHA-256, 5-minute window) and XOR-encrypts delivered payloads to evade static URL scanners. Tycoon2FA — previously the dominant Adversary-in-the-Middle credential-phishing kit, disrupted by a Microsoft/Europol takedown in March 2026 — resurfaced in May 2026 with device code phishing bolted onto its largely intact core kit. The FBI/IC3 issued PSA I-052126-PSA on 21 May 2026, its first advisory naming a specific phishing kit (Kali365), warning that the Telegram-distributed, subscription-based platform lowers the skill barrier via AI-generated lures and real-time victim-tracking dashboards. Barracuda's April 2026 Threat Spotlight logged over 7 million device code attacks in four weeks, describing the technique as fully industrialized under a PhaaS model. A related browser-native technique, ConsentFix (Push Security's Browser & Identity Attacks Matrix ID SAT1051, disclosed December 2025 and initially linked to Russian state-affiliated APT29), abuses trusted first-party OAuth applications and consent-grant flows via a spoofed verification/CAPTCHA page to achieve the same passkey-defeating, post-authentication token theft — evidence that the underlying weakness (authorization-layer trust divorced from authentication-layer defenses) is being exploited through multiple, converging techniques rather than one isolated kit.

Across observed campaigns, Microsoft 365/Entra ID accounts for roughly 99% of detected device code phishing targets, with Salesforce, GitHub, and AWS also confirmed as targeted OAuth 2.0 implementers. Because the flow is a legitimate, spec-compliant protocol feature rather than a software defect, there is no vendor patch; the only effective controls are blocking or conditionally restricting the device authorization grant itself, and behavioral/browser-native detection of the phishing kits' delivery infrastructure rather than IOC-based blocking alone.

## MITRE ATT&CK

- T1598 Phishing for Information
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1199 Trusted Relationship
- T1098 Account Manipulation
- T1528 Steal Application Access Token
- T1110 Brute Force
- T1539 Steal Web Session Cookie
- T1078 Valid Accounts
- T1556 Modify Authentication Process
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1550 Use Alternate Authentication Material
- T1534 Internal Spearphishing
- T1114 Email Collection
- T1530 Data from Cloud Storage
- T1531 Account Access Removal

## Sources

- [6 Reasons Why Device Code Phishing Is Exploding](https://thehackernews.com/2026/07/6-reasons-why-device-code-phishing-is.html)
- [Storm-2372 conducts device code phishing campaign](https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/)
- [Defending SaaS-based applications against ShinyHunters OAuth abuse](https://www.microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse/)
- [Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale](https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/)
- [ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365](https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/)
- [Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens (PSA I-052126-PSA)](https://www.ic3.gov/PSA/2026/PSA260521)
- [Threat Spotlight: Device code phishing is on the rise with 7 million attacks in four weeks](https://blog.barracuda.com/2026/04/23/threat-spotlight-device-code-phishing)
- [How three techniques are behind ShinyHunters' 2026 campaigns (Instructure breach analysis)](https://pushsecurity.com/blog/analyzing-the-instructure-breach)
- [Push Security Uncovers "ConsentFix": A New Class of Browser-Native Phishing Attack](https://pushsecurity.com/news/push-identifies-consent-fix)
- [ConsentFix (SAT1051) — Browser & Identity Attacks Matrix](https://pushsecurity.com/resources/browser-identity-attacks-matrix/consentfix)
- [EvilTokens device-code phishing kit totally more evil than we all thought](https://www.theregister.com/cyber-crime/2026/07/01/eviltokens-device-code-phishing-kit-totally-more-evil-than-we-all-thought/5265409)
- [Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA](https://www.esentire.com/blog/tycoon-2fa-operators-adopt-oauth-device-code-phishing)
- [Analyzing the rise in device code phishing attacks in 2026](https://pushsecurity.com/blog/device-code-phishing)
- [How we built an agentic threat hunting pipeline at Push](https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1793
